In company that i works recently have changed the way to get the OAuth token, they implement a step that decrypt a new client secret that they send to us on the server side.